Appendix C: References and Further Reading¶
The sources below are grouped by category and cited throughout the handbook's parts; each is listed once even where multiple sections reference it.
Standards and Frameworks¶
- NIST Cybersecurity Framework (CSF) 2.0
- NIST Cybersecurity Framework (CSF) 2.0 overview
- NIST Cybersecurity Framework, CSF 2.0 release (February 2024)
- NIST SP 800-207, Zero Trust Architecture
- NIST SP 1800-35, Implementing a Zero Trust Architecture
- NIST SP 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations
- NIST SP 800-61 Revision 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management
- NIST SP 800-63-4, Digital Identity Guidelines
- NIST SP 800-63B, Authentication and Lifecycle Management
- NIST SP 800-92, Guide to Computer Security Log Management
- ISO/IEC 27001:2022
- Center for Internet Security (CIS) Benchmarks
- Cybersecurity Capability Maturity Model (C2M2)
- CISA Zero Trust Maturity Model
- Cloud Security Alliance, Software-Defined Perimeter
- Gartner, Secure Access Service Edge (SASE)
- OWASP Smart Contract Security (SCS) / Smart Contract Security Verification Standard (SCSVS)
- OWASP Web3 Attack Vectors Top 15
- MITRE ATT&CK
- MITRE AADAPT (Adversarial Actions in Digital Asset Payment Technologies)
- Supply-chain Levels for Software Artifacts (SLSA)
- CycloneDX
- SPDX
- FIDO Alliance, FIDO2/WebAuthn
- FIDO Alliance, Passkeys
- EIP-4337, Account Abstraction
- EIP-4361, Sign-In with Ethereum
- BIP-39, Mnemonic Code for Generating Deterministic Keys
- SLIP-0039, Shamir's Secret-Sharing for Mnemonic Codes
- CryptoCurrency Security Standard (CCSS)
- Markets in Crypto-Assets Regulation (MiCA)
- FATF Recommendation 16, the "Travel Rule"
- GDPR Article 33, Notification of a Personal Data Breach
- National Security Decision Directive 298 (1988)
- idmanagement.gov, Federal Identity, Credential, and Access Management
Incidents and Case Studies¶
- Bybit hack summary, Wikipedia
- Bybit official statement, X/Twitter
- Ronin Network incident summary, Wikipedia
- Halborn, Radiant Capital Hack Explained (October 2024)
- Trail of Bits, Supply-Chain Attacks Are Exploiting Our Assumptions (XZ Utils)
- Uber, September 2022 Security Incident Update
- Unit 42, Slow Pisces: New Custom Malware
- FBI Statement on Attribution of Malicious Cyber Activity to Lazarus Group and APT38
- FBI, CISA, and Treasury Joint Advisory AA22-108A, North Korean Cyber Actors Targeting Blockchain Companies
- FBI/IC3 Public Service Announcement PSA250226
- DOJ, Court-Authorized Disruption of North Korean Remote IT Worker Fraud
Tools and Documentation¶
- Chainalysis
- Chainalysis 2025 Crypto Crime Report
- TRM Labs
- Ledger, Ledger Recover
- Safe
- Signal Protocol documentation
- CISA, homepage and layered-security guidance
- CISA, Phishing-Resistant MFA Fact Sheet
- CISA, Tabletop Exercise Packages (CTEPs)
- Google Workspace, Security Checklist for Medium and Large Businesses
- Office of Foreign Assets Control (OFAC)
- FBI Internet Crime Complaint Center (IC3)
- FBI, Counterintelligence